On May 1, anonymous on-chain investigator Wazz reported that hundreds of Ethereum mainnet wallets were drained by what appeared to be a single address, reviving concerns around wallet security and the risks tied to password-management services. A key detail is that many of the affected wallets had been inactive for more than seven years, suggesting the attacker may have gained access to long-stored credentials rather than exploiting a simple phishing attempt or a short-term compromise.
An Unusual Attack Pattern
Based on the available information, the incident is being viewed as a possible new form of real-time attack. Because multiple wallets were emptied in a concentrated manner, and because several of them had shown no activity for years, observers believe the case may reflect a coordinated exploitation of exposed recovery data. For Ethereum holders, the episode is a stark reminder that once a seed phrase or private key is compromised, dormant wallets can still be targeted and emptied at any later date.
Possible Connection to LastPass Secure Notes
Crypto user Capitulation suggested the breach may be tied to users who stored seed phrases in LastPass secure notes during 2020 and 2021. The source material does not establish a final technical conclusion, but the possible connection has intensified scrutiny of third-party storage solutions for sensitive crypto credentials. When seed phrases, private keys, or recovery phrases are kept in online services, even an older security weakness can eventually translate into direct asset losses.
Broader Custody Risks for Crypto Users
The broader lesson from this event is that crypto security extends far beyond the wallet interface itself. It also depends on how recovery information is stored and protected over time. Placing seed phrases in cloud-based password managers, note-taking apps, or other internet-connected tools can create an additional attack surface. For long-term holders especially, inactivity does not eliminate risk. The suspected LastPass angle underscores the ongoing tension between convenience and security in digital asset custody.

